Privacy Policy
Last Updated: September 26th, 2026
Clinia Health Inc. (“Clinia,” “we,” “us,” or “our”) provides technology products and services for healthcare and health-related organizations (the “Services”). This Privacy Policy explains how we collect, use, disclose, retain, protect, and otherwise process Personal Information in connection with our website, business operations, communications, recruitment, and Services.
We understand the importance of privacy and data protection. Our approach reflects the realities of healthcare technology, including enterprise customer relationships, sensitive health information, AI-supported workflows, and deployment models where responsibilities may be shared between Clinia and our customers.
This Privacy Policy helps customers and individuals understand Clinia’s privacy practices. It does not replace any agreement between Clinia and a customer, including a master services agreement, general terms of service, service request, order form, product schedule, data processing addendum, business associate agreement, security terms, Free Tier Services Terms of Service (also called “Freemium Terms”), or similar contractual document (the “Customer Agreement”).
“You” may refer to a customer of our Services (a “Customer”), an authorized user of a Customer, a visitor to our website, or a data subject whose Personal Information is part of Customer Data (defined below).
Key Terms
- “Personal Information” means information about an identified or identifiable individual, as defined under applicable privacy law.
- “Authorized User” means an individual authorized by a Customer to access or use the Services on the Customer’s behalf.
- “End User” means an individual who interacts with the Services or a Customer Application.
Capitalized terms not defined here have the meaning given in the applicable Customer Agreement.
Scope of This Policy
What Is Covered
This Policy applies to Personal Information Clinia collects or processes when you:
- visit or interact with our website;
- communicate with us, including through email, forms, events, sales, support, or other business communications;
- use or access Clinia Services as an Authorized User of a Clinia customer;
apply for a role with Clinia; or - otherwise interact with Clinia in a business, technical, professional, or operational context.
What Is Not Covered
This Policy does not apply to:
- Personal Information handled under a separate Clinia employee or contractor privacy notice;
- websites, applications, services, or integrations operated by third parties; or
- customer-controlled systems, applications, workflows, or environments, except where Clinia processes Personal Information within its own operational scope.
Customer Data
This Policy also explains, at a high level, how Clinia handles Personal Information processed through our enterprise services. That information is often provided to Clinia by, or on behalf of, a Clinia customer. We call this “Customer Data”. Personal Information Clinia processes on behalf of a Customer, as further defined in the applicable Customer Agreement.
If your Personal Information is part of Customer Data, the relevant Clinia customer is generally responsible for explaining its use and responding to privacy requests. Contact that Customer directly unless this Policy or applicable law says otherwise.
Section 7 has more on Customer Data and enterprise services.
Clinia’s Role
Clinia’s Own Processing
For our website, business operations, sales and marketing, customer communications, recruitment, security, and internal administration, Clinia generally determines how and why Personal Information is processed. Depending on applicable law, Clinia may be a controller, business, or similar role for this processing.
Processing on Behalf of Customers
For enterprise services, Clinia often processes Personal Information on behalf of a Customer. The Customer generally determines the purpose of processing, the categories of information submitted, whose information is processed, and the legal basis for use. Depending on applicable law, Clinia may be a processor, service provider, business associate, subcontractor, or similar role. Clinia processes that information under the applicable Customer Agreement.
Personal Information We Collect
What we collect depends on how you interact with us and which services our Customer uses. We collect Personal Information only where reasonably necessary for the purposes in this Policy, our Customer Agreements, or as otherwise permitted or required by law, and we identify our purposes before or at the time of collection unless the law permits otherwise.
Contact and Identity Information
Name, business email, phone number, organization, title, role, and other contact details you provide when communicating with us, requesting information, attending an event, or subscribing to updates.
Account and Authentication Information
Name, email, username, role, organization, authentication status, access permissions, and related account information, if you access Clinia services.
Professional and Business Information
Your organization, professional role, qualifications, affiliations, certifications, responsibilities, business needs, and interactions with Clinia.
Communications and Support Information
Information you provide when contacting us, submitting a form, or participating in a sales or support process, including message content, support requests, and feedback.
Technical, Usage, and Log Information
IP address, device and browser information, operating system, pages viewed, referring URLs, timestamps, authentication events, access logs, system activity, error information, usage metrics, and security logs, collected when you visit our website or use our services. We use this to operate, secure, monitor, support, troubleshoot, and improve our website and services.
Recruitment Information
Name, contact details, resume, employment history, education, qualifications, skills, references, interview notes, and other information you provide when applying for a role.
Customer Data
Clinia’s customers and Authorized Users may submit Personal Information through our services for example, about patients, healthcare providers, customer personnel, or End Users, depending on how the Customer configures and uses the services. This may include your information if you are a patient of a Clinia Customer, or if it is otherwise submitted by a Customer or Authorized User.
Clinia does not control what Customer Data a customer submits. Customer Data is handled under the applicable Customer Agreement.
How We Collect Personal Information
We collect Personal Information from the sources below, depending on the nature of your interaction with us. We only collect from third parties as permitted by law or with your authorization.
Directly From You
When you complete a form, request a demo, communicate with our team, subscribe to updates, attend an event, submit a support request, or apply for a role.
Through Our Website and Services
We automatically collect technical, usage, and log information when you visit our website or use our services, through cookies, similar technologies, application and security logs, authentication records, and monitoring tools.
From Clinia Customers and Authorized Users
When Customers and Authorized Users configure, access, or use our services, or communicate with us about them. Information submitted for a customer’s use of the services is generally Customer Data controlled by the Customer; information provided for support, account management, implementation, billing, security, or procurement may be handled by Clinia as described in this Policy.
From Service Providers and Business Partners
Service providers, business partners, event partners, recruitment and background check providers, security providers, and analytics providers that support our business operations.
From Public or Third-Party Sources
Public sources such as professional networking platforms, company websites, public registries, and business contact databases, used for business development, recruitment, security, compliance, or verification.
From Legal, Regulatory, or Governmental Sources
Courts, regulators, government agencies, or law enforcement, in limited circumstances permitted or required by law.
How We Use Personal Information
We use Personal Information only for the purposes below, depending on the context and services involved.
To Provide and Operate Our Services
Account administration, authentication, access management, customer support, troubleshooting, service communications, and technical operations.
To Communicate With You
Responding to inquiries, providing requested information, managing our relationship, sending administrative messages, and sharing relevant updates.
To Support Customer Relationships and Administer Our Enterprise
Sales communications, contract administration, billing support, implementation coordination, account management, and customer success activities.
To Secure and Protect Our Services
Monitoring for security events, detecting unauthorized access, investigating incidents, preventing fraud, enforcing access controls, maintaining logs, and supporting audit and compliance.
To Improve Our Website, Services, and Operations
Understanding how our website and services are used, evaluating performance, troubleshooting, improving reliability, and developing operational insights, using Personal Information, technical information, usage data, and aggregated data.
Where permitted by the applicable Customer Agreement and law, Clinia may use de-identified, aggregated, anonymized, or non-identifiable technical and operational information (excluding Customer Data) to monitor, maintain, improve, and develop the services,for example, for reliability, performance, security, taxonomy mapping, deduplication, ranking, and matching.
Clinia does not treat information as anonymized, de-identified, aggregated, or non-identifiable unless legal and technical requirements are met. See Section 9 for AI-related processing and training limitations.
To Support Recruitment and Employment Processes
Evaluating applications, communicating with candidates, conducting interviews, assessing qualifications, performing reference or background checks where permitted, and making hiring decisions.
To Comply With Legal and Regulatory Obligations
Complying with applicable laws, legal process, regulatory requirements, contractual obligations, audits, and lawful requests from authorities.
To Protect Rights and Interests
Protecting the rights, property, safety, and interests of Clinia, our Customers, users, partners, and personnel, including enforcing agreements, investigating violations, resolving disputes, and pursuing legal claims.
For Other Purposes With Consent or as Permitted by Law
Other purposes with your consent or as otherwise permitted or required by law.
Legal Bases and Consent
Legal Bases
Clinia processes Personal Information only where we have a lawful basis, which may include:
- your consent;
- performing a contract, or taking steps before entering one;
- Clinia’s legitimate interests, where not overridden by your privacy rights;
- compliance with legal or regulatory obligations;
- protecting vital interests, such as your safety; or
- other purposes permitted or required by applicable law.
Consent
Where consent is required, we seek consent appropriate to the nature, context, and sensitivity of the information, and that is clear, free, informed, and specific. Consent may be express or implied (for example, when you voluntarily provide information to us).
You may withdraw consent where consent is the legal basis for processing, subject to legal restrictions and reasonable notice. Withdrawal may affect our ability to provide certain communications, services, or functionality, but does not affect prior processing or processing otherwise permitted or required by law.
Customer Data and Enterprise Services
Clinia provides enterprise services to healthcare and health-related organizations. Customers and Authorized Users may submit Personal Information through those services, including about patients, healthcare providers, customer personnel, Authorized Users, or End Users, depending on the Customer’s configuration. Clinia does not determine what Customer Data a Customer submits or how the Customer uses it in its own systems.
Customers are generally responsible for:
- deciding whether and how to use the services for their workflows;
- ensuring Customer Data is collected, used, disclosed, and submitted lawfully;
- providing required privacy notices;
- obtaining required consents, authorizations, or other legal bases;
- managing their own Authorized Users and End Users;
- configuring their own systems, integrations, and environments; and
- responding to privacy rights requests relating to Customer Data, unless law or a written agreement provides otherwise.
Clinia uses Customer Data only to provide, secure, support, troubleshoot, monitor, maintain, and improve the applicable services; comply with legal obligations; prevent or address fraud, security incidents, or integrity issues; and as otherwise permitted by the Customer Agreement or Customer instructions. Clinia does not sell Customer Data. Where permitted by the applicable Customer Agreement and applicable law, Clinia may create and use De-identified Data and Aggregated Data derived from Customer Data for the purposes described in the Customer Agreement. The applicable Customer Agreement governs those permissions, safeguards, and uses.
If your Personal Information was submitted by or on behalf of a Clinia Customer, please contact that Customer first. Where required by law, Clinia will support the Customer in responding to your request.
Free Tier and Self-Serve Access
Clinia also offers certain Services on a free, trial, evaluation, preview, demonstration, sandbox, beta, pilot, or proof-of-concept basis (“Free Tier Services”), governed by Clinia’s Free Tier Services Terms of Service (“Freemium Terms”). Clinia does not enter into a Data Processing Addendum, Business Associate Agreement, or other organization-specific privacy, security, or compliance commitment for Free Tier Services access, except where it expressly agrees otherwise in writing.
Free Tier Services are for evaluation, testing, and exploration only. Users should submit only fictitious, synthetic, de-identified, or otherwise non-personal data, and must not submit Protected Health Information where a Business Associate Agreement would be required. Where Personal Information is nonetheless submitted, Clinia handles it under the security and privacy commitments in this Policy and the retention, deletion, and liability terms in the Free Tier Services Terms of Service.
Where an individual accesses Free Tier Services in their own right, rather than on behalf of an organization, that individual is both the Customer and the data subject, and Clinia treats them as a direct data subject under the “Your Privacy Rights and Choices” section below.
Health Information and Sensitive Information
Because Clinia operates in healthcare, Personal Information may include health information, protected health information, or other sensitive categories requiring additional care under applicable law (collectively, “Sensitive Information”).
Clinia handles Sensitive Information within its scope of control under the applicable Customer Agreement, this Policy, and applicable law.
We may process Sensitive Information when a Customer’s configuration or use of the services involves it, for example, information about patients, care teams, healthcare providers, clinical workflows, health records, documents, search queries, prompts, or outputs.
Where Sensitive Information is part of Customer Data, the Customer is generally responsible for deciding whether it may be submitted, providing required notices, obtaining required consents, and ensuring its use complies with applicable healthcare, privacy, professional, and regulatory obligations.
Clinia does not use identifiable Sensitive Information for generalized model training or cross-customer improvement unless the Customer Agreement and applicable law expressly permit it. Where the Customer Agreement and applicable law permit Clinia to create De-identified Data or Aggregated Data from Sensitive Information, those uses are governed by the applicable contractual safeguards.
If you provide sensitive information to Clinia outside the Customer Data context, we will use and disclose it only for the purposes for which it was provided, with your consent where required, or as otherwise permitted or required by law.
AI-Supported Features and Automated Processing
Customer-Controlled AI Workflows
Some services include AI-supported features, automated processing, search, retrieval, summarization, conversational functionality, recommendations, ranking, classification, or analytics.
Where used in enterprise services, the Customer is generally responsible for deciding whether these features fit its use cases, workflows, users, and regulatory obligations. Customer-controlled AI workflows, prompts, retrieval context, outputs, and configurations are governed by the applicable Customer Agreement.
Unless the Customer Agreement and applicable law expressly permit it, Clinia does not use Customer Data, health information, prompts, outputs, clinical content, deployment-specific logs, retrieval results, or Customer-specific evaluation data to train or improve generalized models for use across other Customers.
AI-generated or AI-supported outputs should be reviewed by qualified personnel before use in clinical, operational, professional, or other decision-making. Clinia does not make patient care decisions or determine treatment.
Use of AI at Clinia
Clinia may use AI-supported tools and third-party AI services in its own business operations,for example, in our website, communications, sales and marketing, support, security, recruitment, and administration. These tools may access Personal Information that is not Customer Data to perform their functions.
We do not use this information, or make it available to our AI tools or providers, to train or develop generalized AI models, except with your consent or another lawful basis specifically permitting that use.
Where we engage third-party AI providers, we take reasonable steps to ensure they handle Personal Information only as needed to provide services to Clinia, under appropriate confidentiality, security, and privacy obligations, and not for their own model training.
Automated Processing
Where applicable law gives you rights relating to automated decision-making or profiling, contact us using the details in “Contact Us.” If a Clinia Customer controls the relevant processing, we may direct your request to that Customer or support it in responding, as required by law.
How We Disclose Personal Information
Clinia discloses Personal Information only where reasonably necessary for the purposes in this Policy, as a Customer directs, as the applicable Customer Agreement permits, or as otherwise permitted or required by law.
Affiliates
To Clinia affiliates, where necessary for business operations, service delivery, customer support, administration, security, or compliance.
Service Providers and Subprocessors
To service providers, vendors, subprocessors, contractors, and partners supporting our business and services, for example, providers of cloud infrastructure, hosting, security, monitoring, analytics, customer support, communications, professional services, recruitment, finance, and billing.
These recipients may use Personal Information only as needed to serve Clinia or as otherwise permitted by law, and are subject to appropriate confidentiality, security, and privacy obligations where required. A list of current Subprocessors and key third-party service providers is available at Clinia’s trust center at https://trust.clinia.com/. Customers may receive notice of Subprocessor changes under the applicable Customer Agreement.
Customer-Directed Disclosures and Integrations
Customers may configure our enterprise services to connect with their own systems, applications, identity providers, data sources, analytics tools, or AI/model providers. Personal Information may be disclosed through those integrations based on the Customer’s configuration and instructions. Clinia is not responsible for the privacy practices of third-party services the Customer selects, configures, or controls.
Professional Advisors
To lawyers, auditors, accountants, insurers, and other advisors where reasonably necessary for legal, audit, insurance, financial, governance, or compliance purposes.
Legal, Regulatory, Security, and Compliance Purposes
Where necessary to comply with law, legal process, regulatory requirements, governmental requests, audits, or contractual commitments, or to protect the rights, safety, or interests of Clinia, our customers, users, personnel, or others, including detecting or responding to fraud, security incidents, or misuse.
Business Transactions
In connection with a proposed or completed merger, acquisition, financing, reorganization, sale of assets, due diligence, or similar transaction, with appropriate protections where required by law.
With Consent or as Otherwise Permitted by Law
With your consent or as otherwise permitted or required by applicable law.
Cross-Border Processing and Data Residency
Clinia is based in Canada and may process Personal Information there, in the United States, the European Economic Area, the United Kingdom, or other jurisdictions where Clinia, our affiliates, service providers, or partners operate.
Information processed outside the jurisdiction where it was collected, or where you reside, may be subject to that other jurisdiction’s laws. Clinia takes reasonable steps to protect Personal Information consistent with this Policy, the applicable Customer Agreement, and applicable law, and uses appropriate safeguards for cross-border transfers where required, such as contractual protections, data processing addenda, standard contractual clauses, transfer impact assessments, adequacy decisions, privacy impact assessments, and vendor due diligence.
For Clinia-managed Services, patient information, Health Information, and Protected Health Information are stored and processed in the Canadian or United States workspace region selected when the applicable workspace is created. Customers are responsible for selecting the workspace region appropriate to their legal, regulatory, contractual, and operational requirements. Workspace metadata and other non-sensitive control-plane information may be processed through Clinia’s centralized Canadian infrastructure. Additional hosting, residency, and transfer requirements may be described in the applicable Customer Agreement or other customer-facing materials.
For Customer-managed deployments, the Customer controls the deployment environment, cloud account, infrastructure, network boundary, region, data residency, access management, and logging. In those deployments, patient data, clinical records, and other Customer Data may stay within the Customer-controlled environment unless the Customer configures otherwise.
Where Clinia needs access to Personal Information in a Customer-managed deployment for support, troubleshooting, security, or operations, that access follows the applicable Customer Agreement, product schedule, support process, customer authorization, and applicable law.
Cookies and Similar Technologies
Clinia uses cookies and similar technologies (such as pixels, local storage, SDKs, and tags) on our website and, where applicable, in our services, for example, to:
- enable website and service functionality;
- remember preferences, such as language or region;
- support authentication and secure access;
- understand how our website and services are used;
- measure performance and improve user experience;
- support security, fraud prevention, and service integrity; and
- manage communications, analytics, or marketing, where permitted by law.
Some cookies are necessary for our website or services to function; others are optional. Where we use analytics or other non-essential cookies, we obtain consent where required and provide a cookie preference tool. We honor recognized opt-out signals, including Global Privacy Control, where required by law. You may also manage cookies through your browser, though disabling some cookies may affect functionality.
Cookies used within Clinia products or enterprise services may be limited to those required for authentication, security, session management, or service operation, unless the applicable product documentation or customer agreement says otherwise.
Retention and Deletion
Retention
Clinia retains Personal Information only as long as reasonably necessary for the purposes in this Policy, unless a longer period is required or permitted by law. The period depends on the type of information, its purpose, the services involved, and applicable legal, contractual, security, audit, and dispute-resolution needs.
For example, Protected Health Information and other Customer Data are retained and deleted in accordance with the applicable Customer Agreement and Business Associate Agreement, including any return-or-destruction obligations that apply on termination. Clinia retains HIPAA compliance documentation for at least six years where required by law. Account and authentication information is generally retained for the duration of the business relationship and for up to three years after it ends. Recruitment information for unsuccessful applicants is generally retained for up to two years after the end of the recruitment process or our last contact with the applicant. Website usage and technical log information is generally retained for up to 90 days, unless a longer period is reasonably necessary for security, investigation, legal, compliance, or operational purposes.
Deletion
When Personal Information is no longer required, Clinia deletes, anonymizes, or otherwise handles it under applicable law, our retention practices, and applicable contractual obligations.
Customer Data
Customer Data is retained and deleted under the applicable Customer Agreement, Customer instructions, and applicable law. In Customer-managed deployments, the Customer may control retention and deletion within its own environment.
Backups
Backups, logs, and audit and security records may be retained for limited periods where necessary for security, continuity, compliance, audit, legal, or operational purposes. Where deletion from backups isn’t immediately practicable, we protect that information from further processing except as required or permitted by law.
Security
Clinia maintains reasonable administrative, technical, and organizational safeguards to protect Personal Information against unauthorized access, use, disclosure, alteration, loss, or destruction, appropriate to the nature and sensitivity of the information and the risks involved. These include AES-256 encryption at rest and TLS 1.2+ in transit, within Clinia’s operational scope and for Clinia-managed environments.
Safeguards may include access controls, authentication, role-based permissions, encryption, logging, monitoring, vulnerability management, secure development practices, incident response, personnel training, confidentiality obligations, vendor oversight, and business continuity practices.
Security responsibilities depend on the services, deployment model, Customer configuration, and operational scope. Clinia is responsible for safeguards within its operational control in Clinia-managed environments. For Customer-managed deployments, the Customer is responsible for infrastructure-level controls, cloud account governance, network configuration, identity and access management, monitoring, backups, deployment region, and related security controls.
Clinia does not require unrestricted access to Customer Data. Where support access to Customer Data, environments, logs, prompts, outputs, health information, or other Sensitive Information is needed, it is limited to the approved purpose, authorized personnel, applicable support process, and customer authorization where required.
Clinia maintains security and privacy governance practices, reviewed and improved over time and supported by operational monitoring, vulnerability management, incident response, change management, risk management, and independent assurance activities where applicable.
No security measure guarantees complete security. Customers and users also play a role in protecting Personal Information, including by managing credentials, access permissions, their own environments, integrations, and user activity.
Your Privacy Rights and Choices
Depending on where you are located and how your information is processed, you may have rights over your Personal Information under applicable privacy law. After exercising certain rights, we may no longer be able to provide certain services to you.
These rights may include the right to:
- request access to your Personal Information;
- request correction of inaccurate or incomplete Personal Information;
- request deletion of Personal Information;
- withdraw consent, where processing is based on consent;
- object to or restrict certain processing;
- request information about how Personal Information is collected, used, disclosed, or transferred;
- request portability of Personal Information, where applicable; and
- make a complaint to Clinia or a privacy authority.
To submit a privacy request, contact us using the details in “Contact Us.” We may need to verify your identity first.
Where your request relates to Customer Data, we may direct you to the relevant Customer, who is generally responsible for responding unless applicable law or a written agreement requires otherwise.
Where required, Clinia will support the Customer in responding.
Clinia responds to privacy requests within the time required by applicable law. We may refuse or limit a response where permitted by law ,including where a request affects others’ rights, relates to information we must or may retain, would compromise security or confidentiality, or relates to information controlled by a Clinia Customer.
Children and Minors
Clinia’s website and business services are not directed to children, and we do not knowingly collect Personal Information directly from children.
Because Clinia serves healthcare organizations, Customer Data may include information about minors where a Customer submits or configures the services accordingly. In those cases, the Customer is generally responsible for deciding whether that information may be processed, providing required notices, obtaining required consents, and complying with applicable laws on minors’ information.
If you believe a child has provided Personal Information directly to Clinia without appropriate consent, contact us using the details in “Contact Us.”
Changes To This Policy
Clinia may update this Policy to reflect changes in our services, business operations, legal requirements, privacy practices, or other operational needs.
When we do, we will revise the “Last updated” date above. Where required by law or the change is material, we will provide additional notice, for example, by posting a notice on our website or sending a communication. Where a change involves new processing that requires consent under applicable law, we will seek that consent.
The updated Policy applies from the date posted, or another date stated in the updated version.
Contact Us
If you have questions about this Policy or Clinia’s privacy practices, or wish to submit a privacy request, contact us at:
Clinia Health Inc.
Attention: Privacy Officer / Data Protection Officer
221 de la Commune Street West, Suite 210
Montréal, Québec, Canada, H2Y 2C9
Email: privacy@clinia.com
If your request relates to Personal Information Clinia processes on behalf of a customer, please identify the relevant customer where possible, so we can route your request appropriately. We may refer you to that Customer.
You may also have the right to contact a privacy authority in your jurisdiction. For Québec, the Commission d’accès à l’information du Québec; for Canadian federal matters, the Office of the Privacy Commissioner of Canada; for EEA or UK matters, your local supervisory authority.
For matters involving Protected Health Information subject to US healthcare law, you may also contact the U.S. Department of Health and Human Services, Office for Civil Rights at www.hhs.gov/ocr or 1-800-368-1019.
Jurisdiction-Specific Notices
The attached notice schedules (the “Notices”) provide additional information for individuals in certain jurisdictions or subject to specific privacy laws. These Notices supplement this Policy; where inconsistent, the Notices prevail only for the data subjects they apply to.
Where more than one privacy law applies to the same processing, Clinia follows the most stringent applicable requirement.
Canada
Where the Personal Information Protection and Electronic Documents Act (“PIPEDA”) applies, Clinia collects, uses, and discloses Personal Information only for purposes a reasonable person would consider appropriate.
Clinia identifies its purposes before or at the time of collection unless the law permits otherwise, and limits collection, use, disclosure, and retention to what those purposes reasonably require or the law otherwise permits or requires.
We take reasonable steps to keep Personal Information accurate, complete, and up to date for the purposes we use it, considering its context, sensitivity, and source.
Where consent is required, we seek meaningful consent appropriate to the information’s nature, context, and sensitivity. Consent may be express or implied, depending on the circumstances and applicable law.
Individuals may request access to, or correction of, Personal Information Clinia holds; we respond in accordance with applicable law.
Clinia maintains safeguards to protect Personal Information against unauthorized access, use, disclosure, alteration, loss, or destruction, appropriate to its sensitivity and purpose.
Where Clinia processes Customer Data on behalf of a customer, the customer is generally responsible for determining the purposes of processing, providing required notices, obtaining required consents or other legal bases, and responding to individual rights requests, unless applicable law or a written agreement provides otherwise.
Quebec
Where Québec privacy law applies, including the Act respecting the protection of Personal Information in the private sector, Clinia handles Personal Information under applicable Québec requirements.
Clinia maintains privacy governance practices supporting appropriate handling of Personal Information, including accountability, safeguards, incident response, vendor oversight, and processes for privacy requests.
Where Personal Information is transferred or made accessible outside Québec, Clinia takes the steps required by law, which may include assessing relevant privacy factors and using contractual or other safeguards.
Where Clinia uses technology that can identify, locate, or profile individuals, we provide the information required by law and, where required, activate such functions only under applicable consent or notice requirements.
Where Clinia makes a decision based exclusively on automated processing that affects an individual, we provide the information applicable law requires, including about the automated processing used and the individual’s related rights.
If a confidentiality incident involving Personal Information occurs, Clinia assesses and responds under applicable law, and, where required, notifies the Commission d’accès à l’information, affected individuals, or other required parties, and keeps required incident records.
Individuals may request access to or correction of their Personal Information and exercise other rights available under Québec privacy law, subject to applicable limits, which may include a right to data portability where required by law.
Clinia will not treat information as anonymized unless the applicable legal standard is met.
The person in charge of the protection of Personal Information is identified in the “Contact Us” section above.
EEA / UK GDPR
Where the EU General Data Protection Regulation, the UK GDPR, or related European data protection laws apply (the “GDPR”), Clinia processes personal data under applicable GDPR requirements.
Clinia may act as a controller or processor depending on context. We generally act as a controller for personal data processed in connection with our website, business operations, sales and marketing, customer communications, recruitment, security, and internal administration, and as a processor where we process Customer Data on behalf of a Customer through enterprise services.
Where Clinia is a controller, our legal bases may include consent, contract performance, legal compliance, legitimate interests, or protection of vital interests. We rely on legitimate interests only where not overridden by data subjects’ rights and interests.
Where Clinia is a processor, we process personal data under the Customer’s documented instructions, the applicable Customer Agreement, and other applicable privacy or transfer terms.
Subject to applicable conditions, individuals may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, and information about automated decision-making or profiling, and may lodge a complaint with a competent supervisory authority.
Where personal data is transferred outside the EEA, UK, or Switzerland, Clinia uses the transfer mechanisms and safeguards applicable law requires, such as adequacy decisions, standard contractual clauses, the UK international data transfer addendum, transfer impact assessments, contractual safeguards, and technical and organizational measures.
Where Clinia uses de-identified, aggregated, anonymized, or non-identifiable information (excluding Customer Data) for service improvement, analytics, or operations, we assess whether it remains personal data under applicable European law. Pseudonymized information that remains linkable to an identifiable individual continues to be handled as personal data.
HIPAA
Where the Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”) apply, Clinia may process protected health information (“PHI”) as a Business Associate or subcontractor on behalf of a covered entity or another business associate.
In those cases, Clinia handles PHI under the applicable business associate agreement, HIPAA-specific terms, Customer Agreement, customer instructions, and applicable law, and does not use or disclose PHI except as those permit, as the Customer instructs, or as otherwise permitted or required by law.
Clinia does not de-identify or aggregate PHI except as the Customer expressly permits or instructs. Information derived from PHI is treated under the applicable business associate agreement, HIPAA-specific terms, Customer instructions, and applicable law, and is not treated as de-identified unless the applicable HIPAA standard is met or it otherwise falls outside HIPAA’s scope.
As a Business Associate, Clinia notifies Covered Entity customers of Breaches of Unsecured PHI under the applicable Business Associate Agreement and the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D), and complies with the HIPAA Security Rule (45 C.F.R. §§ 164.308, 164.310, 164.312) for Electronic PHI within our scope of control. Individuals may also contact the U.S. Department of Health and Human Services, Office for Civil Rights at www.hhs.gov/ocr with questions or complaints.
Where Clinia engages subcontractors to process PHI, we require them to comply with applicable US healthcare law under written subcontractor business associate agreements.
The Customer is generally responsible for determining whether HIPAA applies to its use of the services, providing any required HIPAA Notice of Privacy Practices, obtaining required authorizations, and responding to individual requests relating to PHI. This Policy is not a HIPAA Notice of Privacy Practices for any covered entity; individuals with PHI questions should contact the relevant customer directly, unless applicable law or the Customer’s instructions say otherwise.
Individual access requests relating to PHI are the Covered Entity Customer’s responsibility under 45 C.F.R. § 164.524. Where a Customer needs Clinia’s support to respond, we provide it within the timeframe in the applicable Business Associate Agreement or, absent one, within a reasonable period to let the Customer meet its own deadline.
California, USA
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”), applies, this section provides additional information for California residents.
Clinia may act as a “business” or “service provider” depending on context. Generally a business for Personal Information processed in connection with our website, business operations, sales and marketing, customer communications, recruitment, security, and administration, and a service provider where we process Customer Data on behalf of a customer.
We collect the categories of Personal Information described in this Policy, identifiers, contact information, professional or employment information, internet or network activity, commercial or business relationship information, communications, recruitment information, and sensitive Personal Information where applicable, and use them for the purposes described in this Policy.
We may disclose Personal Information to the categories of recipients described above, including affiliates, service providers, subprocessors, customer-directed integrations, professional advisors, legal or regulatory recipients, and parties in business transactions.
Clinia does not sell Personal Information, and does not share it for cross-context behavioral advertising except where applicable law permits and this Policy describes.
Although we don’t sell or share Personal Information, California residents may submit a “Do Not Sell or Share My Personal Information” request to privacy@clinia.com or [privacy request URL]. We confirm receipt within 10 business days, and a “Do Not Sell or Share” link is available on our website as California law requires.
Where Clinia processes Customer Data on behalf of a Customer, we do not sell it or share it for cross-context behavioral advertising, except as the Customer Agreement, Customer instructions, and applicable law expressly permit.
Clinia does not knowingly sell or share Personal Information of individuals under 16.
Where Clinia uses de-identified or aggregated information (excluding Customer Data), we maintain and use it under applicable CCPA requirements, including those preventing re-identification.
Subject to applicable conditions, California residents may have the right to:
- know what Personal Information Clinia collects, uses, discloses, sells, or shares;
- request access to, deletion of, or correction of Personal Information;
- opt out of the sale or sharing of Personal Information;
- limit the use and disclosure of sensitive Personal Information, where applicable; and
- not be discriminated against for exercising CCPA rights.
To exercise these rights, contact us using the details in “Contact Us.” We may need to verify your identity first.
Sensitive Personal Information we may process in connection with our healthcare services includes health information submitted by or about authorized users of our services, used only to provide, operate, secure, and support the Services as described in this Policy and the applicable Customer Agreement. California residents may request that we limit this use by contacting privacy@clinia.com or [privacy request URL].
Authorized Agents: California residents may designate an authorized agent to submit CCPA/CPRA requests on their behalf. We may require written proof of the agent’s authority and may still verify the resident’s identity directly.
Clinia responds to privacy rights requests within 45 days of receipt, with one 45-day extension where reasonably necessary and permitted by law.
Other U.S. State Privacy Laws
Residents of certain U.S. states may have additional privacy rights under applicable state law, which may include the right to access, correct, delete, or port information; learn about processing; opt out of targeted advertising, sales, or profiling/automated decision-making; and appeal a decision on a privacy request.
Clinia honors applicable U.S. state privacy rights where required by law. We do not sell Personal Information, and do not use it for targeted or cross-context behavioral advertising unless this Policy describes it and applicable law permits it, including any required consent or opt-out.
Where Clinia processes Customer Data on behalf of a Customer, we generally act as a processor, service provider, or similar role, and do not sell Customer Data or use it for targeted or cross-context behavioral advertising, except as the Customer Agreement, Customer instructions, and applicable law expressly permit. The Customer is generally responsible for determining the purposes and means of processing, providing required notices, obtaining required consents, and responding to privacy rights requests, unless applicable law or a written agreement provides otherwise.
Where Clinia uses de-identified, aggregated, or non-identifiable information (excluding Customer Data) for service improvement, analytics, or operations, we do so under applicable U.S. state privacy law requirements, and will not treat information as de-identified or outside those laws’ scope unless the applicable legal standard is met.
Clinia responds to privacy rights requests within 45 days of receipt, with one 45-day extension where reasonably necessary and permitted by law.
To appeal a decision on a privacy rights request, submit a written appeal to privacy@clinia.com with the subject line “Privacy Rights Request Appeal,” describing your original request and the decision you’re appealing. We respond to appeals within 60 days of receipt. If your appeal is denied, you may have the right to contact your state’s privacy or data protection authority.